Suspicious
Suspect

0f0f8e2da620d16edcb7ce9fbd62cdb8

VBScript
MD5: 0f0f8e2da620d16edcb7ce9fbd62cdb8
Size: 8.46 MB
text/vbscript

Get an AI-generated breakdown of this malware's behaviour, IOCs and recommendations.

AI analysis is available with Essential.
Unlock with Essential
MD5 0f0f8e2da620d16edcb7ce9fbd62cdb8
Sha1 1f7ebbef32e28c98d29123f26ab98253d5627667
Sha256 d4a2ad392b20b2e4ba82b37ade4fbdcf9c99cd22444241951c2da5fc4b675948
Sha384 70b81aeae5782294206418f54c12c5f41d2e640789e01a3ef4863503026e5d750ea69b002c2638946a7ee1a2d39eb084
Sha512 e63e1f9004706f1a476fc2228753c912f33ae5be2f43247a470afb5576c0d6a2e1405aff4694a99d474ecfabb61159752e3f5dfb033058b0c618a79f48c22777
SSDeep 196608:XNCIFVS+z7WXVLCcRZN5qib0HMtJPpTTwxRxFoPDHJAti:93VS+Qdsibl3dTwc7uw
TLSH B48633C6BCC624FAD09BD7749683B26D702A3FCABC73CD4E729A7A540E716162072741
Root Entry
䡀䌏䈯
䡀䈖䌧䠤
䡀䌋䄱䜵
䄰䑬䞁䄦䠥
䡀㬿䏲䐸䖱
䡀㽿䅤䈯䠶
䡀䈏䗤䕸䠨
䡀䓞䕪䇤䠨
䡀䕙䓲䕨䜷
䡀䌍䈵䗦䕲䠼
䡀䒌䓰䑲䑨䠷
Overlay_960fdf95.bin
Structure
DosHeader
PE Header
Optional Header (x64)
Section Headers
.text
.rdata
.data
.pdata
.$Ne
.0<e
.9?s
.rsrc
.reloc
Resources
RT_MANIFEST
ID:0002
ID:1033
䡀㼿䕷䑬㭪䗤䠤
䡀㼿䕷䑬㹪䒲䠯
䡀㿿䏤䇬䗤䒬䠱
䡀䖖㯬䏬㱨䖤䠫
䡀䘌䗶䐲䆊䌷䑲
䡀䄕䑸䋦䒌䇱䗬䒬䠱
䡀䇊䌰㾱㼒䔨䈸䆱䠨
䡀䈏䗤䕸㬨䐲䒳䈱䗱䠶
䡀䑒䗶䏤㾯㼒䔨䈸䆱䠨
䡀䇊䌰㮱䈻䘦䈷䈜䘴䑨䈦
䡀䇊䗹䛎䆨䗸㼨䔨䈸䆱䠨
䡀䑒䗶䏤㮯䈻䘦䈷䈜䘴䑨䈦
SummaryInformation
STICH beta Structural Threat Infection Chain Hash

A content-independent fingerprint of the infection method: successive formats, internal objects and MITRE techniques from the initial file to each final payload.

Structural branches: 3 STICH kept: 1secondary ignored: 2
bin 2

Decorative / non-determinant leaves (styles, themes, media, fonts, icons, plain text…) are summarized here instead of producing STICH Paths.

STICH Path = the fingerprint (canonical chain with techniques) STICH Shape = structure only Only determinant branches produce STICH Paths.
Path ole:doc>pe:dll>scr:vbs
Shape ole:doc>pe:dll>scr:vbs
3 nodes
Root Entry
䡀䌏䈯
䡀䈖䌧䠤
䡀䌋䄱䜵
䄰䑬䞁䄦䠥
䡀㬿䏲䐸䖱
䡀㽿䅤䈯䠶
䡀䈏䗤䕸䠨
䡀䓞䕪䇤䠨
䡀䕙䓲䕨䜷
䡀䌍䈵䗦䕲䠼
䡀䒌䓰䑲䑨䠷
Overlay_960fdf95.bin
Structure
DosHeader
PE Header
Optional Header (x64)
Section Headers
.text
.rdata
.data
.pdata
.$Ne
.0<e
.9?s
.rsrc
.reloc
Resources
RT_MANIFEST
ID:0002
ID:1033
䡀㼿䕷䑬㭪䗤䠤
䡀㼿䕷䑬㹪䒲䠯
䡀㿿䏤䇬䗤䒬䠱
䡀䖖㯬䏬㱨䖤䠫
䡀䘌䗶䐲䆊䌷䑲
䡀䄕䑸䋦䒌䇱䗬䒬䠱
䡀䇊䌰㾱㼒䔨䈸䆱䠨
䡀䈏䗤䕸㬨䐲䒳䈱䗱䠶
䡀䑒䗶䏤㾯㼒䔨䈸䆱䠨
䡀䇊䌰㮱䈻䘦䈷䈜䘴䑨䈦
䡀䇊䗹䛎䆨䗸㼨䔨䈸䆱䠨
䡀䑒䗶䏤㮯䈻䘦䈷䈜䘴䑨䈦
SummaryInformation
No malware configuration was found at this point.
You must be signed in to view YARA rules.
An error has occurred. This application may no longer respond until reloaded. Reload 🗙